Your message dated Fri, 21 Aug 2026 11:19:37 +0000
with message-id <[email protected]>
and subject line Bug#1144955: fixed in wordpress 7.1+dfsg1-1
has caused the Debian Bug report #1144955,
regarding wordpress: CVE-2026-65640
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144955: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144955
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: wordpress
Version: 7.0.3+dfsg1-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for wordpress.
CVE-2026-65640[0]:
| WordPress is vulnerable to a remote code execution vulnerability via
| malicious Postscript file upload by an Author level user or higher.
| Prerequisites: * Imagick and Ghostscript in use on the server * A
| malicious user with the `upload_files` capability This issue
| affects all versions of WordPress. Version 7.0.4 has been released,
| containing a fix for the vulnerability, and as a courtesy to users
| on older branches the fix has been backported to all branches back
| to 4.7.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-65640
https://www.cve.org/CVERecord?id=CVE-2026-65640
[1] https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
[2]
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 7.1+dfsg1-1
Done: Craig Small <[email protected]>
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 21 Aug 2026 20:58:18 +1000
Source: wordpress
Architecture: source
Version: 7.1+dfsg1-1
Distribution: unstable
Urgency: medium
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1144955
Changes:
wordpress (7.1+dfsg1-1) unstable; urgency=medium
.
* New upstream release
Includes security fix from 7.0.4 CVE-2026-65640 Closes: #1144955
* Remove patch remove_remote_emojis as no longer needed
* Remove version of php-getid3 as forky has newer
* Add build-dep php-phpmailer for linktree
* Remove translation package as its out of date mostly
Checksums-Sha1:
eefc24a7fed6b9b29a8f5626b84f80fe8edc2e6c 2345 wordpress_7.1+dfsg1-1.dsc
6da24c93ddde9927548b0f89badb5fd03b6b21e2 28026200
wordpress_7.1+dfsg1.orig.tar.xz
b15d0d39487a6a3438ba4dcd5d2e212c536b679d 1603208
wordpress_7.1+dfsg1-1.debian.tar.xz
1bd22f54eeb49abe9e37c06285a6e73fad893cea 7196
wordpress_7.1+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
4de06bc1fc48160be40c00b775d6b33adcda66c7502ebc881465a9eb51316067 2345
wordpress_7.1+dfsg1-1.dsc
1dc614f5d24e81d0753a5ecc544ed51fe26cf4855288970d69ad7a86efd19585 28026200
wordpress_7.1+dfsg1.orig.tar.xz
3cbd3c57181967e4005f5b12fc18774ecc5b89edc6652ae853e20de5cb35a713 1603208
wordpress_7.1+dfsg1-1.debian.tar.xz
fe1ad516b4dfd6f48e698310e5451c28c5a339227934e0aa9a25634ab204f827 7196
wordpress_7.1+dfsg1-1_amd64.buildinfo
Files:
b6b4cb804e6cc9b75fae311c22870260 2345 web optional wordpress_7.1+dfsg1-1.dsc
e77c9aa918ab89e71a698d455fe6c2ad 28026200 web optional
wordpress_7.1+dfsg1.orig.tar.xz
a17455678a22cce76ec4b700d73698b4 1603208 web optional
wordpress_7.1+dfsg1-1.debian.tar.xz
fbc48ec1e803d113803ab6790716240b 7196 web optional
wordpress_7.1+dfsg1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmqIL7cACgkQAiFmwP88
hOME9A/8DTKR6EWcxVIdYZoB01XwQuUrbs6XWqcAv72iUAaHSopCWGfgNK35lN41
Mo6uskJmUJMqzXvdaFOvg524obPg55pYJ9EFRlb8BUepyHTldrG7D9XZXlEuaLXS
jZyObJyo1FQob36MnU9EJkfLgRgDYSEbAiY4okMggSkIHWhJIXam1HV73RBEDZHX
Q48vkXewLxBos2ENEMUTj89vcZl3xrOw6ucyNu6K6/LpDdXgBav4GqCDhm/WFj0p
pZOr7UraXHZBAmtfT+VELK7CEOzgW0XacgahVZAK+MVU021eYmuyhVfZh38V5c7s
DynN3IvFR8roRjZhNlAVh/3vx6lQ3Ks6UPPmEFQd4cYbJPDmrsy+U3n/Awx7XW8N
MOX8+ucRx/BVHzpcN0xzjHQR1oSoVnQ/hwgnCMhljmEt56/vxbVLysmft05bWuS8
pylRtXajEaWJOZgCo7T5nLWcx/Bmlss1ajH0sMDxYuIvICl+y/HZvPOkoErOmvmU
zLW2UllbNPWCBWGLp5ykGZRJfW0wff9hp5WmKZfRBSHGEDxalr/H+fjEBpP/Hfsf
/aWAMiilf8+9CVogA2JZ5lODMiXTEF2sVdwtm2UcPxOVVoZU9wlfE6KJ+vyBIUEb
t2VY/B95emyjq1L3uhmGUKXZktTMO7RIJmwFWE3oNGRSYe/v77I=
=t0oH
-----END PGP SIGNATURE-----
pgpyN_891RjT8.pgp
Description: PGP signature
--- End Message ---